Canonical Framework Canonical Frameworks Moderate

FedRAMP Moderate

FedRAMP Moderate baseline covering 325+ NIST SP 800-53 Rev. 5 controls. Required for cloud services handling controlled unclassified information (CUI). Includes continuous monitoring, vulnerability management, incident response, and sovereign-region deployment. Aligned to CISA BOD 22-01.

Regions

US

Regulations

4 covered

Control Domains

7 domains

Deployment

Sovereign Region, Fully Air-gapped

Regulations & Standards

FedRAMP Authorization Act (44 USC § 3609) NIST SP 800-53 Rev 5 Moderate NIST SP 800-171 Rev 2 CISA BOD 22-01

Control Domains

Access Control
Audit Logging
Incident Response
Data Encryption
Vulnerability Management
Configuration Management
Continuous Monitoring

Deployment Options

Sovereign Region
Fully Air-gapped

Get started in 3 steps

1

Explore the template

Click "Explore in Console" to open this template in the Keeptrusts configuration editor.

2

Customize policies

Adjust detection thresholds, escalation rules, and redaction patterns to match your requirements.

3

Deploy to your gateway

Save your configuration and deploy it to any Keeptrusts gateway — cloud, on-prem, or air-gapped.